Data processing addendum.

Last updated 6 September 2026

This addendum applies whenever a school, district or other education institution uses Bluestift with its students. It forms part of the agreement between us and sets out what we do with student data, and what we will never do with it.

Short version: the school owns the data, we only process it to run the service, we do not sell it, we do not use it to build a profile for any purpose other than tutoring that student, and we give it back or destroy it when the school says so.

1. Who is who

The school is the controller of its students' personal data and decides what is collected and why. We are the processor and act only on the school's documented instructions — using the service as configured counts as those instructions.

For students who sign up on their own, outside any school, we are the controller and our privacy policy governs instead.

2. What we process

  • Subject matter: providing an AI tutor and a staff dashboard.
  • Duration: the term of the school's subscription, plus the deletion window in §9.
  • Data subjects: the school's students and its staff.
  • Categories: identity (name, class, year), account data, work submitted to the tutor, assessment results, and the learning signals derived from them.

3. FERPA — we act as a school official

The school designates us a school official with a legitimate educational interest in student education records under 34 CFR § 99.31(a)(1). On that basis we commit that:

  • We perform a function the school would otherwise perform with its own staff.
  • We are under the school's direct control with respect to the use and maintenance of education records.
  • We use education records only for the purpose the school engaged us for, and do not re-disclose them to anyone else except as §5 permits.
  • We maintain a record of disclosures of a student's record, which the school can request.

Inspect and review. A parent or eligible student exercises that right with the school. Staff can produce a student's record from the dashboard at any time. That record covers identity, enrolment, results, inferred understanding and staff notes — but not the student's own conversations with Raya, for the reason set out in §7.

4. COPPA — consent for under-13s

Outside any school, a child under 13 can use Raya on their own under our privacy policy — no analytics, no model training, no public rooms, no purchase without a stated adult. The moment a school enrols them, this addendum and the school's consent govern instead.

By enrolling students under 13, the school confirms that it consents on behalf of their parents for the school's educational use, as the COPPA school-consent exception permits (16 CFR § 312.5(c)(6)), and that it has given parents notice of what we collect. We collect from children only what the service needs, never condition participation on more, and never use a child's data for advertising or profiling outside tutoring. On a parent's request, relayed by the school, we delete a child's data.

5. Sub-processors

We use the providers listed on our sub-processors page, which also states, honestly, which of those agreements are already signed and which are still being put in place — we have only just launched. Whatever their status, we remain responsible to you for what those providers do.

We update that page and notify school administrators before a new sub-processor starts handling school data. A school may object on reasonable data protection grounds within 30 days; if we cannot offer an alternative, the school may terminate the affected part of the service and be refunded the unused balance.

6. Security

  • Data is encrypted in transit and at rest by our infrastructure provider.
  • Access is enforced in the database itself with row-level security, so a teacher reaches their own classes and no others — not merely because the interface hides the rest.
  • Staff access is scoped by role, and privileged operations run server-side only.
  • Everyone with access is bound to confidentiality.

Breach notification. If we suffer a personal data breach affecting a school's data, we notify that school without undue delay and in any event within 72 hours of becoming aware, with what we know and what we are doing about it.

7. What we will not do

  • We do not sell student data. There is no circumstance in which we would.
  • We do not serve advertising, and we do not build advertising profiles.
  • We do not use student or staff content to train models unless the account holder explicitly opted in — it is never switched on by default on a school-linked account — and that option is not available to under-18s, which is every student in a school setting below sixth form.
  • We do not give staff a student's private tutoring conversations. A student who believes their tutor is being read stops asking the questions that make tutoring work, so the staff record covers what the student produced and what the system inferred, not the transcript. The student, or a parent through the student, can export the transcript in full.

8. Helping the school meet its obligations

We assist the school with data subject requests (access, correction, deletion, portability), with data protection impact assessments, and with regulator enquiries. Most requests are answerable directly from the dashboard; where they are not, write to hello@thebluestift.com. If a data subject comes to us directly, we refer them to the school rather than acting on our own.

We make available the information needed to demonstrate compliance with these obligations and allow for audits, on reasonable notice and without disrupting the service for other schools.

9. Return and deletion

At any time during the term the school can export its students' records. When the contract ends, we delete school data within 90 days at the school's choice of deletion or return, except where a law requires us to keep something — payment records being the usual case.

Deletion is real. It reaches the learning content, the uploads, the assessment results and the inferred learning model, including the parts held in systems that no automatic cascade would have reached.

10. International transfers

Where a sub-processor operates outside the EEA or the UK, transfers must be covered by the European Commission's Standard Contractual Clauses or an adequacy decision. The location of each provider, and the current status of that cover, is on the sub-processors page.

This page states the commitments we make to every school on the same terms. It is not legal advice. A school that needs a countersigned document, or its own paperwork on top of this, should write to hello@thebluestift.com and we will arrange it.